166 terms · 75/46/45
Threat № 027 · class: social eng.

Spear Phishing

Spear phishing is phishing cut to fit one person or a small group of users. Instead of sending the same message to thousands of addresses, the attacker first gathers information about the victim — where they work, who they work with, what they are working on right now, how the company addresses its clients — and then writes a message that reads as if it came from that world.

Term

description · examples · notes

Spear phishing is phishing cut to fit one person or a small group of users. Instead of sending the same message to thousands of addresses, the attacker first gathers information about the victim — where they work, who they work with, what they are working on right now, how the company addresses its clients — and then writes a message that reads as if it came from that world.

Description

It is exactly that personalization that makes spear phishing far more successful than the mass kind. The message does not smell of fraud: it refers to a real project, a real name, a real deadline. The attacker knows they do not have to reach many people — one right person with the right access is enough. That is why it pays them to spend weeks preparing a single message.

The defense is harder than with mass phishing, because technical filters have less to catch — the message is clean, targeted, without the usual spam patterns. The weight therefore falls on the person and on the process: checking unusual requests through another channel (a call, in person), two-factor authentication, and the rule that urgency and authority in a message are a sign to verify rather than to comply.

Examples

  • An email that refers to a real, recent internal meeting, with the minutes attached — and the attachment carrying malware.
  • A message apparently from the director, requesting an urgent transfer of funds while they are travelling and unreachable.
  • A personalized email with a link to a document tied to the very project the victim is working on.

Notes

  • The groups behind advanced persistent threats (APT) almost always begin with spear phishing — it is their cheapest way into a well-defended network.
  • The more publicly visible a person is (company site, LinkedIn, conferences), the easier a target they are; reducing unnecessary public detail is part of the defense.

Mentioned in the news

Composite
Wikipedia

Techniques

carried out with 6

Defenses

countered by 8